Description
Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2098
Related Vulnerabilities
CVE-2020-4076 Vulnerability in npm package electron
CVE-2023-28679 Vulnerability in maven package javagh.jenkins:mashup-portlets-plugin
CVE-2020-13929 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2023-32977 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-job
CVE-2015-0254 Vulnerability in maven package taglibs:standard